Skip to main content

Data Governance

Compliance Engine produces sensitive data about your environment. Data governance ensures that this information is protected, retained appropriately, and auditable.

Access Control

Findings, policies, and exceptions can reveal details about vulnerabilities and misconfigurations. Ensure that:

  • Access is restricted to users who need it (for example, security, compliance, platform teams).
  • Auditors have read‑only access where necessary.
  • Highly sensitive findings are segmented if your organization requires it.

Use Cloudaware’s roles and permission sets to enforce these boundaries.

Retention

Decide how long to retain:

  • Findings (including closed ones) for historical analysis and audits.
  • Exceptions and approval records.
  • Reports and evidence artifacts stored in external repositories.

Retention decisions should align with regulatory requirements and internal records management policies.

Audit Logging

Changes to policies, exceptions, and key configuration should be traceable. Consider:

  • Enabling and reviewing change logs for policy code and metadata.
  • Tracking who approved exceptions and when.
  • Recording exports of compliance data where required by regulation.

Strong data governance around Compliance Engine data supports both internal oversight and external audits.